Apache Tomcat's XML parser handling flaws, CVE-2014-0119 and CVE-2013-4590, could allow a malicious application deployed on a shared Tomcat instance to access sensitive information. CVE-2014-0119 allowed an application to replace XML parsers used by the default servlet, potentially bypassing external-entity limits or reading XML files belonging to other applications; CVE-2013-4590 enabled application-supplied XML files to resolve external entities and potentially bypass Java SecurityManager restrictions.
Red Hat released updated tomcat6 packages for RHEL 6, including tomcat6-6.0.24-78.el6_5, and advised administrators to restart Tomcat after applying the update. Affected organizations should use vendor-provided backports or upgrade to fixed upstream releases: Tomcat 6.0.41, 7.0.53, 8.0.5, or later; Tomcat 6 is now end of life and no longer receives security fixes.

See real exploitation activity before you spend the cycle.
8 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2014:1038 for RHEL 6, supplying backported tomcat6 fixes including tomcat6-6.0.24-78.el6_5. The update addressed XML external-entity and XML-parser replacement issues, and Red Hat advised users to update and restart Tomcat.
Red Hat issued RHSA-2014:1034 for RHEL 7, providing tomcat-7.0.42-8.el7_0 and related packages with a backported fix for CVE-2014-0119. The advisory advised administrators to update and restart Tomcat to prevent malicious web applications from replacing XML parsers and accessing XML processed by other applications.
CVE-2014-0119, an information-disclosure flaw caused by replacement of XML parsers used in Tomcat XSLT processing, was reported. A remote unauthenticated attacker could use a specially crafted application to obtain sensitive information.
CVE-2013-4590 was published for an XML external entity vulnerability in Apache Tomcat that could disclose internal Tomcat information through an untrusted web application containing a crafted XML document. Affected releases included Tomcat versions before 6.0.39, 7.0.50, and 8.0.0-RC10.
Ubuntu published security notice USN-2654-1 addressing Tomcat vulnerabilities. The provided reference does not specify the affected versions, CVEs, or release date.
Red Hat released a Moderate-impact security update for JBoss EAP 6.2.4 addressing CVE-2014-0075, CVE-2014-0099, CVE-2014-0096, and CVE-2014-0119. The update mitigated denial-of-service, HTTP request-smuggling, XXE, and XML-parser replacement issues; Red Hat advised customers to apply it and restart JBoss.
Red Hat released JBoss Data Grid 6.3.0 to replace version 6.2.1, fixing moderate-impact flaws including JBoss Web denial-of-service, request-smuggling, XXE, and XML-parser hijacking issues. The release also fixed plaintext and world-readable audit-log issues (CVE-2014-0058 and CVE-2014-0059) and added configurable audit logging and masking controls.
JBoss Web incorporated a fix for CVE-2014-0119 in version 7.4.7.Final, preventing malicious web applications from replacing XML parsers and accessing XML processed by other applications on the same instance.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
18 references tracked. Mallory keeps watching after this page renders.
exchange.xforce.ibmcloud.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcelinux.oracle.com
Open sourcebugzilla.redhat.com
Open sourceseclists.org
Open sourcemandriva.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.